Vulnerability Name:

CVE-2009-3518 (CCN-53515)

Assigned:2009-09-30
Published:2009-09-30
Updated:2009-10-02
Summary:Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.
CVSS v3 Severity:6.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
5.8 Medium (CCN CVSS v2 Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-94
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2009-3518

Source: CCN
Type: Retrogod Web Site
IBM Installation Manager <= 1.3.0 iim:// uri handler remote code execution exploit - IE

Source: MISC
Type: Exploit
http://retrogod.altervista.org/9sg_ibm_uri.html

Source: CCN
Type: SA36906
IBM Installation Manager "iim" URI Handling Argument Injection

Source: SECUNIA
Type: Vendor Advisory
36906

Source: CCN
Type: IBM Web site
IBM Installation Manager

Source: CCN
Type: OSVDB ID: 58420
IBM Installation Manager IBMIM.exe iim: URL Library Argument Injection Arbitrary Code Execution

Source: CCN
Type: BID-36549
IBM Installation Manager 'iim://' URI Handling Remote Code Execution Vulnerability

Source: VUPEN
Type: Vendor Advisory
ADV-2009-2792

Source: XF
Type: UNKNOWN
installationmanager-ibmim-code-execution(53515)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:installation_manager:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:installation_manager:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:installation_manager:1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:installation_manager:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:installation_manager:*:*:*:*:*:*:*:* (Version <= 1.3.2)

  • Configuration CCN 1:
  • cpe:/a:ibm:installation_manager:1.3.2:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:rational_team_concert:2.0.0.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm installation manager 1.0
    ibm installation manager 1.2.1
    ibm installation manager 1.3.0
    ibm installation manager 1.3.1
    ibm installation manager *
    ibm installation manager 1.3.2
    ibm rational team concert 2.0.0.1